Closed tender

Home Office Border Force Security Architecture & Assurance Service

Details

Value
GBP 5,000,000
Published
29 June 2017
Submission
13 July 2017

Tender description

Why the Work is Being Done Border Force has a requirement for Technical Security Information Assurance and Design capabilities to shape and lead the overall security architecture for Border Force portfolios, programmes and projects using open standards (such as TOGAF). Other Home Office programmes may also make use of this arrangement. Problem to Be Solved Border Force would like to grow and augment its current Technical Security Information Assurance and Design capability. In order to do this, it needs to engage a partner to work with the current team on several programmes. Who Are the Users Users include the public applying for entry to or the right to remain in the UK and police, security and enforcement teams controlling immigration and securing UK borders and detecting criminal behaviour within the Home Office and wider Government Agencies. Early Market Engagement No market engagement has taken place. Work Already Done There are currently resources in place, where the current contract with an incumbent supplier is coming to an end. Existing Team There is an existing team in place working within Border Force. The new supplier will need to work collaboratively with other areas of the Programme and other suppliers. Current Phase Not applicable Work Location Lunar House, Croydon and Marsham Street, London, as well as other Home Office locations on request. Working Arrangments The team need to be able to operate within a hub and spoke governance model and with other third parties if required. The team is expected to work across the multiple sites, the main site is expected to be Croydon and be available during standard HO working hours. Expenses will conform to HO internal policies and will not be payable within the M25. Security Clearance Service Provider personnel need to be compliant with SC clearance, and in certain circumstances, DV clearance. Additional T&Cs Individual Statements of Work agreed periodically subject to satisfactory performance and HO needs. Contract is non-exclusive. Intention is service provision with defined outcomes; supplier is responsible for deliverables, risk, and provision of individuals. If this was to be executed in this manner then it would probably be deemed outside the intermediaries’ legislation but could be affected by factors outside HO control. HO assumes no liability; will grant no guarantee of status. Supply-continuity, resource-stability, and management part of assessment criteria; excessive dependence on independent contractors may be detrimental to bid evaluation unless within managed supply-chains. HO will own developed technology IPR. Skills & Experience Demonstrable evidence of significant experience (5 years preferred) and deep expertise across a broad spectrum of Information Assurance methodologies. Significant experience (3 years+) providing Information-Assurance Services for solutions built within Agile-delivery lifecycles/continuous delivery to production, ensuring gating processes followed, design/code reviews performed and security issues/risks appropriately addressed. Demonstrable evidence of capability to shape and lead the overall security architecture using open standards (such as TOGAF). Capability to develop/implement/maintain an Information Assurance roadmap and the supporting implementation plan based upon Agile delivery for programmes & projects, plus gap analysis between current & target states. Demonstrable evidence of experience of assuring IaaS, SaaS, PaaS solution in hyper scale cloud providers. Demonstrable evidence of capability to manage the end-to-end Information Assurance process and provision of lifecycle support including end-to-end risk management. Capability to impart operational security advice to Border-Force projects (e.g. coordinating application security testing, providing detailed SOWs to external ITHC providers and working with development teams on key risks). Demonstrable experience with commercial risk assessment methodology e.g. ISF and IRAM. Demonstrable experience with ISO27001:2013 and risk assessment methodology. Demonstrable evidence of experience implementing NCSC (CESG) security guidelines, standards, and policies. Demonstrable experience of technical governance within projects delivered to the GDS service standards and production of appropriate artefacts as projects move through delivery, alpha, beta and into live service. Nice to Haves Have successfully established Intelligent Client Functions to direct and assure deliverables from internal and external suppliers. Demonstrable experience of assuring projects and find out where they are going wrong and what is required to remediate. Demonstrable evidence of strong stakeholder management showing staff with experience of managing expectations and reporting to a wide range of internal departmental and cross-Government stakeholders, including those at senior level. Demonstrable experience in Border security and Immigration requirements and business processes, issues, and solutions. Demonstrable experience of working on digital by default service standard compliant government website. Demonstrable experience of writing of specific operations guidelines e.g. decommissioning of Laptops etc. Guidance will be stipulated by the security architects. Demonstrable experience of writing of specific operations guidelines e.g. decommissioning of Laptops etc. Guidance will be stipulated by the security architects. Demonstrable experience of establishing & running Key operations functions e.g. running vulnerability scanning tools & write up results; Installing specific security tools e.g. password safes. Demonstrable experience of establishing/running Key operations functions e.g. Decommissioning servers/laptops/end point user devices; Installing/running open-source security tools e.g. clamAV,NGINX WAF, pfSense firewall; Managing PKI infrastructure e.g. issuing CA. Demonstrable experience of Incident Management reporting including defining processes. Demonstrable experience of supporting Dev Ops in respect to delivery of specific security controls, particular in respect of using cloud providers. Demonstrable experience of assuring and securing solutions built at Official and Secret data classifications. Demonstrable evidence of designing technical controls for solutions in hyper scale cloud providers. Demonstrable evidence of designing technical controls for solutions in hyper scale cloud providers. Demonstrable evidence of designing technical controls for solutions in hyper scale cloud providers. Demonstrable evidence of chairing Security Working Groups and Information Assurance Boards Demonstrable evidence of strong understanding of GPDR legislation. Demonstrable evidence of defining and implementing automated security tests. Demonstrable evidence of building an in-house PEN test capability. Demonstrable evidence of providing a business concentric view on information risks. No. of Suppliers to Evaluate 5 Proposal Criteria All essential and nice to have requirements will be evaluated further as part of the overall proposal criteria below There will be 6 Evaluation criteria weighted: Specific Competencies 65%, Methodology 10%, Plan for initial phase 10%, Ability to scale capability 10%, Performance Management 5%, Risk Management 5% Specific Competencies: Includes all essential and nice to have technology criteria Methodology: Knowledge and application of Agile, Government Digital Service, and NCSC standards. Plan: Quality of delivery plan for first phase of engagement and statement of work Scale Capability: Capability of increasing delivery or service capability in the medium to long term Performance: Delivery and Service management reliability and repeatability - Client reporting and Quality management. Risk Management: Provide evidence of maintaining quality and consistency over the medium term and approach to assumption, dependency, risk, and issue management Cultural Fit Criteria Approach to service readiness. Approach to stakeholder management. Approach to developing a One Team approach. Approach to the development of client capability. Approach to people development. Approach to innovation and value for money. Payment Approach Capped time and materials Assessment Method Written proposal Evaluation Weighting Technical competence 65% Cultural fit 5% Price 30% Questions from Suppliers Budget range £4 - £5 million across the lifetime of the contract.

Timeline

  1. Completed: Tender published29 June 2017
    Current notice
  2. Completed: Submission date13 July 2017

About the buyer

Home Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Home Office Border Force Security Architecture & Assurance Service, ranked by notice volume.

View all topics
TopicCountValue
  1. 1,485
    £14.9bn
  2. 5,684
    £136.4bn
  3. 343
    £2.3bn
  4. 2,074
    £309.9bn
  5. 3,366
    £105.8bn
  6. 2,507
    £313.9bn
  7. 1,418
    £20.1bn
  8. 4,088
    £269.5bn

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.